Impact
The vulnerability is an Use of Hard‑coded Credentials flaw in Dell Secure Connect Gateway (SCG) 5.0. An unauthenticated attacker with remote access can leverage the embedded default credentials to log in. This leads to unauthorized information exposure, potentially revealing configuration data or other sensitive information stored by the appliance or application, but does not provide arbitrary code execution.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected.
Risk and Exploitability
The CVSS score of 4.4 indicates low to moderate severity. The EPSS score is not available, but the lack of a KEV listing suggests no widely known exploitation activity. The flaw can be exploited remotely over the network by an unauthenticated attacker, so it is important to patch or otherwise restrict access.
OpenCVE Enrichment